CVE-2025-59536: Claude Code MCP Config Command Execution
A vulnerability in Claude Code allowed project-level MCP configuration to lead to command execution.
Critical and exploited CVEs, vulnerability intelligence and remediation guidance.
A vulnerability in Claude Code allowed project-level MCP configuration to lead to command execution.
CVE-2025-54136, known as MCPoison, is a vulnerability in Cursor discovered by Check Point Research. It allows an attacker to get an MCP…
A vulnerability in Windsurf allowed attacker-controlled content to rewrite local MCP config and register a malicious server, leading to command execution.
A critical vulnerability in the Linux kernel's traffic-control subsystem, tracked as CVE-2026-46331 and nicknamed 'pedit COW,' allows a local unprivileged user to…
A recently disclosed flaw in the Linux kernel's act_pedit Traffic Control subsystem, known as pedit COW, allows unprivileged users to escalate privileges…
A Linux kernel flaw in the Dirty Frag family that allows local privilege escalation when CAP_NET_ADMIN is set. It was among the…
CVE-2026-46300, known as Fragnesia, bypassed the DirtyFrag patch through a flag-dropping bug in skb_try_coalesce(). It allowed local privilege escalation by exploiting the…
A new Linux kernel privilege escalation vulnerability, tracked as CVE-2026-43503 and nicknamed DirtyClone, has been publicly disclosed with a working exploit. Discovered…
A Linux kernel flaw known as DirtyClone that allows local privilege escalation when CAP_NET_ADMIN is set. It was among the vulnerabilities targeted…
A Linux kernel flaw in the Dirty Frag family that allows local privilege escalation when CAP_NET_ADMIN is set. It was among the…